![Cisco VPN 3000 Скачать руководство пользователя страница 275](http://html.mh-extra.com/html/cisco/vpn-3000/vpn-3000_user-manual_2609334275.webp)
Configuration | Policy Management | Traffic Management | Security Associations | Add or Modify
13-25
VPN 3000 Concentrator Series User Guide
Perfect Forward Secrecy
This parameter specifies whether to use Perfect Forward Secrecy, and the size of the numbers to use, in
generating Phase 2 IPSec keys. Perfect Forward Secrecy is a cryptographic concept where each new key
is unrelated to any previous key. In IPSec negotiations, Phase 2 keys are based on Phase 1 keys unless
Perfect Forward Secrecy is specified. Perfect Forward Secrecy uses Diffie-Hellman techniques to
generate the keys.
Click the drop-down menu button and select the Perfect Forward Secrecy option:
Disabled
= Don’t use Perfect Forward Secrecy. IPSec Phase 2 keys are based on Phase 1 keys. This
is the default selection.
Group 1 (768-bits)
= Use Perfect Forward Secrecy, and use Diffie-Hellman Group 1 to generate IPSec
Phase 2 keys, where the prime and generator numbers are 768 bits. This option is more secure but
requires more processing overhead.
Group 2 (1024-bits)
= Use Perfect Forward Secrecy, and use Diffie-Hellman Group 2 to generate IPSec
Phase 2 keys, where the prime and generator numbers are 1024 bits. This option is most secure but
requires the most processing overhead.
Lifetime Measurement
This parameter specifies how to measure the lifetime of the IPSec SA keys, which is how long the IPSec
SA lasts until it expires and must be renegotiated with new keys. It is used with the
Data Lifetime
or
Time
Lifetime
parameters below.
Click the drop-down menu button and select the measurement method:
Time
= Use time (seconds) to measure the lifetime of the SA (the default). Configure the
Time
Lifetime
parameter below.
Data
= Use data (number of kilobytes) to measure the lifetime of the SA. Configure the
Data Lifetime
parameter below.
Both
= Use both time and data, whichever occurs first, to measure the lifetime. Configure both
Time
Lifetime
and
Data Lifetime
parameters.
None
= No lifetime measurement. The SA lasts until the connection is terminated for other reasons.
Data Lifetime
If you select
Data
or
Both
under
Lifetime Measurement
above, enter the number of kilobytes of payload
data after which the IPSec SA expires. Minimum is
100
KB, default is
10000
KB, maximum is
2147483647
KB.
Time Lifetime
If you select
Time
or
Both
under
Lifetime Measurement
above, enter the number of seconds after which the
IPSec SA expires. Minimum is
60
seconds, default is
28800
seconds (8 hours), maximum is
2147483647
seconds (about 68 years).
Содержание VPN 3000
Страница 36: ......
Страница 42: ......
Страница 68: ......
Страница 94: ......
Страница 96: ......
Страница 118: ......
Страница 124: ......
Страница 150: ......
Страница 178: ......
Страница 202: ......
Страница 206: ......
Страница 250: ......
Страница 296: ...14 Administration 14 2 VPN 3000 Concentrator Series User Guide Figure 14 1 Administration screen ...
Страница 344: ......
Страница 444: ......
Страница 480: ......